
EvilVM
Forth-based compiler deployed as position-independent x86_64 shellcode, providing a remote code execution agent with interactive REPL over TCP, HTTP,…

Forth-based compiler deployed as position-independent x86_64 shellcode, providing a remote code execution agent with interactive REPL over TCP, HTTP,…

CVE-2026-42945 Nginx Rift

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

POC for CVE-2024-4701

Explore RootSec's DDOS Archive, featuring top-tier scanners, powerful botnets (Mirai & QBot) and other variants, high-impact exploits, advanced…

[POC] Asynchronous reverse shell using the HTTP protocol.

Adversary Emulation Framework

Go-based proof-of-concept exploit for CVE-2026-23918 targeting a double-free vulnerability in Apache httpd mod_http2, enabling pre-auth remote code…

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Exploit Java deserialization vulnerabilities in WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS using Python PoC scripts and crafted HTTP requests.

HTTP Server serving obfuscated Powershell Scripts/Payloads

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)